Two instruments, not one
People say "GDPR cookie consent", but two separate instruments are doing the work, and they answer different questions. The ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) governs the act of storing information on, or reading information from, a visitor’s device. Article 5(3) says that needs consent, whatever the information is and whether or not it is personal data. The only exceptions are transmission and services the subscriber explicitly requested.
The GDPR then defines what consent has to look like. Article 4(11) requires it to be freely given, specific, informed and unambiguous, expressed by a statement or a clear affirmative action. Article 7 adds that you must be able to demonstrate it, that the request must be distinguishable from other matters, and that withdrawing it must be as easy as giving it. The Court of Justice settled the obvious follow-up question in Planet49 (C-673/17): a pre-ticked box is not a clear affirmative action.
Put together, that is the whole shape of a compliant banner. Nothing optional before the choice, a refusal that is no harder than acceptance, a record you can produce later, and the ability to change your mind.
The 30 countries the runtime treats as GDPR
Detection is by ISO 3166-1 alpha-2 country code, resolved at configuration-fetch time. The set is the 27 EU member states plus the three EEA EFTA states, because the ePrivacy and GDPR regimes were incorporated into the EEA Agreement.
- EU: Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Sweden
- EEA EFTA: Iceland, Liechtenstein, Norway
The United Kingdom is detected separately
A visitor from GB resolves to UK GDPR, not GDPR, because the two regimes have diverged since 2021. The consent model is the same; the regulator, the penalty ceilings and the emerging exceptions are not.
What each region profile resolves to
A property has one region profile. It decides how a detected jurisdiction becomes a consent model for the visitor in front of you. For an EEA visitor, three of the four profiles agree.
| Region profile | Resolved model | What the visitor sees |
|---|---|---|
| Regional defaults | opt-in | Nothing optional loads until a choice is made |
| Global strict | opt-in | Nothing optional loads until a choice is made, everywhere |
| Global balanced | opt-in | Nothing optional loads until a choice is made |
| EU and UK opt-in | opt-in | Nothing optional loads until a choice is made |
An opt-in model means the runtime creates no loader for an optional technology until its category has been granted. That is enforced in the engine, not in the banner: hiding the banner, blocking it with an ad blocker, or navigating before answering all leave the same result, which is that nothing optional ran.
Demonstrating consent, which is the part that gets audited
Article 7(1) puts the burden of proof on the controller. A screenshot of a banner does not discharge it, because it says nothing about what any individual visitor was shown or chose. What StrongPrivacy keeps for each decision is the property, the pseudonymous visitor key, the categories granted and refused, the resolved region, the source that recorded it, the timestamp, and the exact configuration version that was live at that moment.
That last field is what makes the record defensible. Banner copy, category descriptions and the technology list all change over time; a decision that cannot be tied to the wording in front of the visitor when they made it is a decision you cannot explain. Configurations are versioned and immutable once published, so the record points at something that can still be read.
- Records are exportable as CSV from the workspace
- Retention runs from 12 months on Free and Starter to 36 months on Agency
- Decisions survive configuration changes; a privacy-relevant republish is what prompts a fresh choice, and appearance-only changes are not
Configuring a property for the EEA
- 1
Scan before you configure
Run a verification scan against the site as it stands. The pre-consent baseline tells you what is loading today with no choice made, which is the list you actually have to bring under control.
- 2
Map every finding to a category
Necessary, functional, analytics, marketing and media ship by default, and you can add custom purposes with their own stable keys and their own stored decisions. Anything that builds a profile belongs in marketing regardless of what the vendor calls it.
- 3
Keep the refusal as prominent as the acceptance
The default copy offers "Accept all" and "Reject optional" at the same level. Regulators across the EEA have treated a missing or buried reject control as a defect in the consent itself.
- 4
Translate the banner
A banner in a language the visitor does not read is not informed consent. Translations are per property and a published configuration can carry up to 60 languages; the runtime matches the visitor’s browser languages against them and falls back to the property default.
- 5
Verify after publishing
Scan again in each state (before consent, after rejection, after approval) and look at what the browser actually did, not at what the configuration says it should do.
What is at stake
GDPR infringements of the consent provisions sit in the higher tier of Article 83(5): up to €20 million or 4% of total worldwide annual turnover, whichever is higher. ePrivacy penalties are set nationally and vary. Supervisory authorities may also order processing to stop or require corrective work; the outcome depends on the authority, law and facts.
This is a product reference, not legal advice
It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.
Common questions
Does the GDPR require a cookie banner?
Neither instrument mentions banners. Article 5(3) of the ePrivacy Directive requires consent before storing or reading information on a device, and the GDPR sets the standard that consent must meet. A banner is simply the interface almost everyone uses to collect it. A site that sets only strictly necessary cookies needs no consent for them, and may not need a banner at all.
Are analytics cookies exempt from consent in the EU?
Not generally. Some supervisory authorities (France’s CNIL most explicitly) publish conditions under which a narrowly configured, first-party audience-measurement setup may be exempted, but the conditions are strict and are national rather than EEA-wide. Treating analytics as consent-required is the defensible default, and it is what StrongPrivacy does out of the box.
Is legitimate interest an alternative to consent for cookies?
Not for the storage-and-access step. Article 5(3) of the ePrivacy Directive requires consent specifically, and it is lex specialis: a legitimate-interest assessment under the GDPR does not substitute for it. Legitimate interest may still be the basis for what you do with the data afterwards, which is a separate analysis.
How long can consent last before you have to ask again?
No instrument sets a figure. Several supervisory authorities suggest revisiting at least every six to twelve months, and StrongPrivacy defaults a new property to 180 days, which you can change per property. A privacy-relevant change to the configuration also prompts a fresh choice, because the old decision was made about different wording.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Regulation (EU) 2016/679 (GDPR)
Legislation
Checked
- Directive 2002/58/EC (ePrivacy Directive)
Legislation
Checked
- Court of Justice of the European Union: Planet49 (C-673/17)
Official documentation
Checked
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.